Detecting an attack usually means noticing behavior, not malware files. Indicators of compromise (IoCs) are artifacts that suggest a system has been breached: known bad IP addresses and domains, file hashes, unusual registry keys, strange processes or log entries. Indicators of attack focus on behaviors in progress. As an SSCP you will review alerts and logs, so you need to recognize the common patterns of attacker activity after initial access.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.